Re: openldap: gdb: symbol lookup error: /lib64/libldap.so.2: undefined symbol: EVP_md2, version OPENSSL_3.0.0

2023-03-27 Thread Dmitry Belyavskiy
fedoraproject.org > Fedora Code of Conduct: > https://docs.fedoraproject.org/en-US/project/code-of-conduct/ > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines > List Archives: > https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org > D

Re: openldap: gdb: symbol lookup error: /lib64/libldap.so.2: undefined symbol: EVP_md2, version OPENSSL_3.0.0

2023-03-28 Thread Dmitry Belyavskiy
? > Which is better to fix the gdb or openldap? > > Jun > > On Mon, Mar 27, 2023 at 5:45 PM Dmitry Belyavskiy wrote: > > > > Dear Jan, > > > > Yes. gdb expects system openssl (providing this function) > > > > To workaround it, you have to provide t

How to get a rawhide i686 VM?

2023-05-15 Thread Dmitry Belyavskiy
nable choice. Any advice would be appreciated! -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/pr

Re: How to get a rawhide i686 VM?

2023-05-15 Thread Dmitry Belyavskiy
Dear Peter, On Mon, May 15, 2023 at 1:06 PM Peter Robinson wrote: > > On Mon, May 15, 2023 at 11:39 AM Dmitry Belyavskiy > wrote: > > > > Dear colleagues, > > > > What is the simplest way to get a rawhide i686 VM? I came across a > > nasty architecture-s

Managing multiple cross-dependent patches

2023-06-02 Thread Dmitry Belyavskiy
? I’m aware of quilt and git-absorb but it looks like they don’t help me much. Many thanks! -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of

Re: Managing multiple cross-dependent patches

2023-06-02 Thread Dmitry Belyavskiy
Dear Chris, On Fri, Jun 2, 2023 at 4:42 PM Chris Adams wrote: > > Once upon a time, Dmitry Belyavskiy said: > > I maintain OpenSSH that has a lot of heavy-interfering downstream > > patches. I’d like to reduce the burden of rebase by combining some of > > them. > &g

Re: Managing multiple cross-dependent patches

2023-06-02 Thread Dmitry Belyavskiy
Dear Daniel, On Fri, Jun 2, 2023 at 4:57 PM Daniel P. Berrangé wrote: > > On Fri, Jun 02, 2023 at 04:27:37PM +0200, Dmitry Belyavskiy wrote: > > Dear colleagues, > > > > I maintain OpenSSH that has a lot of heavy-interfering downstream > > patches. I’d like to

Re: Changes to build environment

2023-06-22 Thread Dmitry Belyavskiy
iling_list_guidelines > List Archives: > https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org > Do not reply to spam, report it: > https://pagure.io/fedora-infrastructure/new_issue -- Dmitry Belyavskiy ___

OpenSSH: hardening hostkeys permissions

2022-12-07 Thread Dmitry Belyavskiy
able https://src.fedoraproject.org/rpms/openssh/pull-request/37 A separate question is whether we want to publish this announcement as a Fedora change and at what level. For me it looks like a self-contained change. -- Dmitry Belyavskiy ___ devel ma

Re: OpenSSH: hardening hostkeys permissions

2022-12-08 Thread Dmitry Belyavskiy
Dear Daniel, Thanks for your feedback! On Wed, Dec 7, 2022 at 2:55 PM Daniel P. Berrangé wrote: > On Wed, Dec 07, 2022 at 01:48:48PM +0100, Dmitry Belyavskiy wrote: > > The problem we expect is that after reverting the patch we can lose the > > remote access to the hosts be

Re: OpenSSH: hardening hostkeys permissions

2022-12-08 Thread Dmitry Belyavskiy
On Thu, Dec 8, 2022 at 3:51 PM Daniel P. Berrangé wrote: > On Thu, Dec 08, 2022 at 03:41:32PM +0100, Dmitry Belyavskiy wrote: > > Dear Daniel, > > Thanks for your feedback! > > > > On Wed, Dec 7, 2022 at 2:55 PM Daniel P. Berrangé > > wrote: > > > &g

Heads-up: new OpenSSL build changes

2023-01-13 Thread Dmitry Belyavskiy
uring PKCS#1 v1.5 decryption. This is a general protection against issues like CVE-2020-25659 and CVE-2020-25657. This protection can be disabled by calling `EVP_PKEY_CTX_ctrl_str(ctx, "rsa_pkcs1_implicit_rejection". "0")` in the RSA decryption contex

Heads-up: OpenSSL update

2023-02-09 Thread Dmitry Belyavskiy
ld be rolled up earlier. Many thanks in advance! -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/pr

Re: Heads-up: OpenSSL update

2023-02-09 Thread Dmitry Belyavskiy
Dear Paul On Thu, Feb 9, 2023 at 6:56 PM Paul Wouters wrote: > > On Thu, 9 Feb 2023, Dmitry Belyavskiy wrote: > > > I've just pushed updates of OpenSSL to the 3.0.8 version to f36/37. > > I will also push to f38 and rawhide later today. > > Why is f36/f3

Re: Heads-up: OpenSSL update

2023-02-10 Thread Dmitry Belyavskiy
Alexandre Salim wrote: > > Hi Dmitry, > > On Thu, 2023-02-09 at 18:02 +0100, Dmitry Belyavskiy wrote: > > Dear colleagues, > > > > I've just pushed updates of OpenSSL to the 3.0.8 version to f36/37. > > I will also push to f38 and rawhide later today. >

Re: Heads-up: OpenSSL update

2023-02-10 Thread Dmitry Belyavskiy
Dear Michel, On Fri, Feb 10, 2023 at 7:06 PM Michel Alexandre Salim wrote: > > Dear Dmitry, > > On Fri, 2023-02-10 at 09:55 +0100, Dmitry Belyavskiy wrote: > > Dear Michel, > > > > In RHEL/CentOS we currently provide a double versioning for > > OPENSS

Adding liboqs to Rawhide

2023-02-13 Thread Dmitry Belyavskiy
afe/liboqs/blob/40b01fdbb270f8614fde30e65d30e9da18c02393/src/common/rand/rand_nist.c#L1-L15 What is the proper line for the spec file and what are my next steps to evaluate the licenses, if necessary? Many thanks in advance! -- Dmitry Belyavskiy ___ dev

Fedora rawhide (to be f41) and openssl engines

2024-07-22 Thread Dmitry Belyavskiy
and if yes, what is the mechanism for such a change. -- Dmitry Belyavskiy -- ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject

Re: Fedora rawhide (to be f41) and openssl engines

2024-07-22 Thread Dmitry Belyavskiy
Dear Zbyszek, On Mon, Jul 22, 2024 at 2:57 PM Zbigniew Jędrzejewski-Szmek wrote: > > On Mon, Jul 22, 2024 at 01:34:39PM +0200, Dmitry Belyavskiy wrote: > > So I wonder if it's worth changing the engine deprecation mechanism in > > Fedora to the one we have in CentOS

Re: Fedora rawhide (to be f41) and openssl engines

2024-07-22 Thread Dmitry Belyavskiy
ith the new one. I'm ready to help if necessary, and Clemens made a great job explaining people what's going on while I was on PTO -- Dmitry Belyavskiy -- ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an emai

OpenSSL performance tuning Webinar

2024-07-23 Thread Dmitry Belyavskiy
Dear colleagues, OpenSSL has announced the performance tuning webinar on August 1 https://openssl.org/blog/blog/2024/07/18/August-Webinar/ Feel free to register and join -- Dmitry Belyavskiy -- ___ devel mailing list -- devel

Re: How to contact Fedora Security Team

2024-08-18 Thread Dmitry Belyavskiy
e of Conduct: > https://docs.fedoraproject.org/en-US/project/code-of-conduct/ > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines > List Archives: > https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org > Do not reply to spam, report it

Heads-up: post-quantum libs landed in Fedora rawhide

2023-07-19 Thread Dmitry Belyavskiy
sues or at least raise bugs upstream. We also expect that there are both applications and protocol specifications that are not capable of dealing with the keys that are neither RSA nor EC/EdDDSA and also would like the issues to be raised. -- Dmitry

Dropping of sshd.socket unit

2023-08-03 Thread Dmitry Belyavskiy
.cgi?id=2025716. -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Gu

Re: Dropping of sshd.socket unit

2023-08-15 Thread Dmitry Belyavskiy
ctions to an sshd server, configured using socket activation can cause the socket to be disabled permanently ("sshd.socket: Trigger limit hit, refusing further activation."). On Mon, Aug 7, 2023 at 11:48 AM Lennart Poettering wrote: > > On Do, 03.08.23 11:29, Dmitry Belyavsk

Re: status openssl1.1

2023-10-16 Thread Dmitry Belyavskiy
n impact of the > removal are these 3 components: > > gloo-0.5.0^git20230824.01a0c81-6.fc40.src.rpm > opensmtpd-6.8.0p2-12.fc39.src.rpm > python3.6-3.6.15-20.fc39.src.rpm I'm afraid it's too late for removing the compat package in F40. If not, I can raise the change proposa

Re: status openssl1.1

2023-10-16 Thread Dmitry Belyavskiy
Dear Peter, On Mon, Oct 16, 2023 at 1:43 PM Peter Robinson wrote: > > On Mon, Oct 16, 2023 at 10:05 AM Dmitry Belyavskiy > wrote: > > > > On Mon, Oct 16, 2023 at 10:21 AM Petr Pisar wrote: > > > > > > V Mon, Oct 16, 2023 at 08:55:12AM +0200, j

Re: status openssl1.1

2023-10-18 Thread Dmitry Belyavskiy
Dear Miro, On Tue, Oct 17, 2023 at 10:33 PM Miro Hrončok wrote: > > On 16. 10. 23 14:19, Dmitry Belyavskiy wrote: > >> Why is it too late for F-40? Do you mean F-39? > > > > Thanks! > > https://fedoraproject.org/wiki/Changes/RemoveOpensslCompat > > Could

Re: OpenSSL 3.2.1 available in rawhide

2024-02-09 Thread Dmitry Belyavskiy
kID=113198856 > > The tests pass locally in mock with openssl 3.1.4. I can imagine the situation where upgrading to 3.2 could cause this failure but the logs are too vague. Could you please provide more details (e.g. openssl low-level diagnostics) or even better a minimal repro

Heads-up: OpenSSL sync with RHEL

2022-09-05 Thread Dmitry Belyavskiy
rt in a similar way as it is done in RHEL. -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/pr

Karma for OpenSSL needed

2022-11-01 Thread Dmitry Belyavskiy
Dear colleagues, I've just pushed the updates for OpenSSL fixing 2 CVEs evaluated as HIGH. Could you please check the freshly pushed builds to get necessary karma ASAP? Many thanks! -- Dmitry Belyavskiy ___ devel mailing list --

Re: Karma for OpenSSL needed

2022-11-01 Thread Dmitry Belyavskiy
're note rebasing to 3.0.7 or generally updating > in Fedora with 3.x? It looks like 3.0.6 had CVE-2022-3358 which hasn't > been addressed because we're still on .5 > Applying a separate patch takes several minutes, and rebasing is some process, usually much longer. The r

Re: F41 Change Proposal: Disable openSSL Engine Support (system-wide)

2024-03-20 Thread Dmitry Belyavskiy
t; > > == Summary == > > We disable support of engines in OpenSSL > > > > == Owner == > > * Name: [[User:Dbelyavs| Dmitry Belyavskiy]] > > * Email: dbely...@redhat.com > > > > == Detailed Description == > > We are going to build OpenSSL wi

Re: F41 Change Proposal: Disable openSSL Engine Support (system-wide)

2024-03-20 Thread Dmitry Belyavskiy
= Summary == > > We disable support of engines in OpenSSL > > > > == Owner == > > * Name: [[User:Dbelyavs| Dmitry Belyavskiy]] > > * Email: dbely...@redhat.com > > > > == Detailed Description == > > We are going to build OpenSSL without engine support.

Re: F41 Change Proposal: Disable openSSL Engine Support (system-wide)

2024-03-20 Thread Dmitry Belyavskiy
Dear Fabio, On Wed, Mar 20, 2024 at 3:18 PM Fabio Valentini wrote: > On Wed, Mar 20, 2024 at 3:06 PM Daniel P. Berrangé > wrote: > > > > On Wed, Mar 20, 2024 at 02:35:21PM +0100, Dmitry Belyavskiy wrote: > > (...) > > > > As I understand, upstream is goi

Re: F41 Change Proposal: Disable openSSL Engine Support (system-wide)

2024-03-20 Thread Dmitry Belyavskiy
Dear Daniel, On Wed, Mar 20, 2024 at 3:06 PM Daniel P. Berrangé wrote: > On Wed, Mar 20, 2024 at 02:35:21PM +0100, Dmitry Belyavskiy wrote: > > Dear Daniel, > > > > On Wed, Mar 20, 2024 at 1:44 PM Daniel P. Berrangé > > wrote: > > > > > On Fri, Mar 0

Re: F41 Change Proposal: Disable openSSL Engine Support (system-wide)

2024-03-21 Thread Dmitry Belyavskiy
Dear Jun, On Thu, Mar 21, 2024 at 11:04 AM Jun Aruga (he / him) wrote: > On Wed, Mar 20, 2024 at 2:36 PM Dmitry Belyavskiy > wrote: > > > ... > >> > == Detailed Description == > >> > We are going to build OpenSSL without engine support. Eng

Re: F41 Change Proposal: Disable openSSL Engine Support (system-wide)

2024-03-21 Thread Dmitry Belyavskiy
Dear Zbyszek, On Thu, Mar 21, 2024 at 12:41 PM Zbigniew Jędrzejewski-Szmek < zbys...@in.waw.pl> wrote: > On Thu, Mar 21, 2024 at 12:15:43PM +0100, Dmitry Belyavskiy wrote: > > > > Hi Dmitry, > > > Could you provide the upstream OpenSSL project's issue ticke

Re: F41 Change Proposal: Disable openSSL Engine Support (system-wide)

2024-03-21 Thread Dmitry Belyavskiy
Dear Jun, On Thu, Mar 21, 2024 at 2:29 PM Jun Aruga (he / him) wrote: > On Thu, Mar 21, 2024 at 12:16 PM Dmitry Belyavskiy > wrote: > > > > Dear Jun, > > > > > > > > On Thu, Mar 21, 2024 at 11:04 AM Jun Aruga (he / him) > wrote: > >>

Re: xz backdoor

2024-03-29 Thread Dmitry Belyavskiy
_ > devel mailing list -- devel@lists.fedoraproject.org > To unsubscribe send an email to devel-le...@lists.fedoraproject.org > Fedora Code of Conduct: > https://docs.fedoraproject.org/en-US/project/code-of-conduct/ > List Guidelines: https://fedoraproject.org/wiki/Mailing_lis

Re: Three steps we could take to make supply chain attacks a bit harder

2024-03-30 Thread Dmitry Belyavskiy
of the other available approaches. Arch Linux is also systemd-based > nowadays, but still does not link OpenSSH against libsystemd. We have an upstream-adjusted version of this patch, see https://bugzilla.mindrot.org/show_bug.cgi?id=2641 I'm OK to bring the updated version

Re: Three steps we could take to make supply chain attacks a bit harder

2024-03-30 Thread Dmitry Belyavskiy
esis is completely wrong. Having, say, a 30+ downstream patches and declining to run upstream tests is the most effective way to break a gazillion use-cases. But the fuzzing tests look quite dangerous to me here and now. No one can review a corpse of binary files :( -- Dmitry Belya

Re: F41 Change Proposal: OpenSSL Deprecate Engine (system-wide)

2024-04-02 Thread Dmitry Belyavskiy
a separate > -devel file, e.g. openssl-engine-devel, mark it as Provides: deprecated(). > Existing packages which need the engine headers can adjust to use the > new header and new packages are prevented by the Packaging Guidelines > from adding a dependency on deprecated packages. >

Re: F41 Change Proposal: OpenSSL Deprecate Engine (system-wide)

2024-04-02 Thread Dmitry Belyavskiy
S#11 are not aware of any Yubikey issues, BTW. Third-party engines may be a problem but as we don't break ABI, it's not a problem of the moment. -- Dmitry Belyavskiy -- ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscrib

Re: F41 Change Proposal: OpenSSL Deprecate Engine (system-wide)

2024-04-02 Thread Dmitry Belyavskiy
Dear Gary, On Tue, Apr 2, 2024 at 5:39 PM Gary Buhrmaster wrote: > On Tue, Apr 2, 2024 at 3:12 PM Dmitry Belyavskiy > wrote: > > > Third-party engines may be a problem but as we don't break ABI, it's not > a problem of the moment. > > The fact you are re

Re: F41 Change Proposal: OpenSSL Deprecate Engine (system-wide)

2024-04-03 Thread Dmitry Belyavskiy
Dear Zbyszek, Thanks, I updated the Wiki page correspondingly. On Wed, Apr 3, 2024 at 5:56 PM Zbigniew Jędrzejewski-Szmek < zbys...@in.waw.pl> wrote: > [Replying to two mails at once to conserve some electrons.] > > On Tue, Apr 02, 2024 at 04:03:31PM +0200, Dmitry Belyavskiy wr

Re: F41 Change Proposal: OpenSSL Deprecate Engine (system-wide)

2024-04-03 Thread Dmitry Belyavskiy
reventing "providers" from working in all use cases in which > "engines" work) is NOT reasonable. > You are 100% correct. That's why disabling this API is not on the table for now anymore. -- Dmitry Belyavskiy -- ___ devel m

Re: F41 Change Proposal: Make OpenSSL distrust SHA-1 signatures by default (system-wide)

2024-06-09 Thread Dmitry Belyavskiy
etected but the data should not > be trusted any more than an unsigned domain. > > To be able to distinguish between cases 2 and 3, the resolver must > remain able to verify SHA-1 signatures. > Looks reasonable to me. -- Dmitry Belyavskiy --

Re: F41 Change Proposal: Make OpenSSL distrust SHA-1 signatures by default (system-wide)

2024-06-09 Thread Dmitry Belyavskiy
would make things _much_ easier. > We don't plan to provide such an API, sorry. SHA1 is insecure. It should be eliminated from the crypto contexts _before_ a second-preimage attack starts to cost $0.02 -- Dmitry Belyavskiy -- ___ devel mailing l

Re: F41 Change Proposal: Make OpenSSL distrust SHA-1 signatures by default (system-wide)

2024-06-09 Thread Dmitry Belyavskiy
Dear Roberto On Sun, Jun 9, 2024 at 1:16 PM Roberto Ragusa wrote: > On 6/9/24 11:27, Dmitry Belyavskiy wrote: > > > > On Sun, Jun 9, 2024 at 11:22 AM Zbigniew Jędrzejewski-Szmek < > zbys...@in.waw.pl <mailto:zbys...@in.waw.pl>> wrote: > > >

Re: F41 Change Proposal: Make OpenSSL distrust SHA-1 signatures by default (system-wide)

2024-06-11 Thread Dmitry Belyavskiy
___ > devel mailing list -- devel@lists.fedoraproject.org > To unsubscribe send an email to devel-le...@lists.fedoraproject.org > Fedora Code of Conduct: > https://docs.fedoraproject.org/en-US/project/code-of-conduct/ > List Guidelines: https://fedoraproje

Re: HEADS UP: openssl engine-related FTBFS and Boost

2024-07-02 Thread Dmitry Belyavskiy
viders. I'd recommend consider it as a gentle reminder about future engine deprecation -- Dmitry Belyavskiy -- ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Con

Re: Self Introduction: Pavel Odintsov

2022-05-28 Thread Dmitry Belyavskiy
ist_guidelines > List Archives: > https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org > Do not reply to spam on the list, report it: > https://pagure.io/fedora-infrastructure > -- Dmitry Belyavskiy ___ devel mai

Can't login into Wiki

2022-06-22 Thread Dmitry Belyavskiy
f Fedora System-wide proposals deadline? Many thanks in advance! -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproje

Re: F37 proposal: Deprecate openssl1.1 package (System-Wide Change)

2022-06-24 Thread Dmitry Belyavskiy
age, we will provide strong enough motivation to get rid of the deprecating packages. -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct:

Re: F37 proposal: Deprecate openssl1.1 package (System-Wide Change)

2022-06-24 Thread Dmitry Belyavskiy
On Fri, Jun 24, 2022 at 11:20 AM Daniel P. Berrangé wrote: > On Fri, Jun 24, 2022 at 11:13:13AM +0200, Dmitry Belyavskiy wrote: > > On Wed, Jun 22, 2022 at 11:02 PM Miro Hrončok > wrote: > > > > > On 22. 06. 22 21:05, Vipul Siddharth wrote: > > > > We ar

Re: F37 proposal: Deprecate openssl1.1 package (System-Wide Change)

2022-06-24 Thread Dmitry Belyavskiy
lected_alpn_protocol_if_server_uses_alpn > (test.test_ssl.ThreadedTests) > -- > Traceback (most recent call last): > File "/home/rjones/d/cpython-2.7/Lib/test/test_ssl.py", line 3045, in > test_selected_alpn_pro

Re: F37 proposal: Deprecate openssl1.1 package (System-Wide Change)

2022-06-29 Thread Dmitry Belyavskiy
s://fedoraproject.org/wiki/Mailing_list_guidelines > List Archives: > https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org > Do not reply to spam on the list, report it: > https://pagure.io/fedora-infrastructure > -- Dmitry Belyavskiy __

Re: F37 proposal: Deprecate openssl1.1 package (System-Wide Change)

2022-06-29 Thread Dmitry Belyavskiy
Dear Miro, On Wed, Jun 29, 2022 at 5:27 PM Miro Hrončok wrote: > On 29. 06. 22 17:11, Dmitry Belyavskiy wrote: > > Dear colleagues, > > > > If I correctly follow the discussion, the biggest show-stopper is Python > 2.*, > > which has some incomplete patches to

Re: help needed on AskFedora: OpenSSLv3 error when connecting to Eduroam

2022-06-30 Thread Dmitry Belyavskiy
raproject.org/archives/list/devel@lists.fedoraproject.org > Do not reply to spam on the list, report it: > https://pagure.io/fedora-infrastructure > -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an e

Re: kTLS related failures on rawhide in OpenSSL 3.0.1

2022-01-19 Thread Dmitry Belyavskiy
hives: > https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org > Do not reply to spam on the list, report it: > https://pagure.io/fedora-infrastructure > -- Dmitry Belyavskiy ___ devel mailing list -- deve

Re: kTLS related failures on rawhide in OpenSSL 3.0.1

2022-01-20 Thread Dmitry Belyavskiy
On Thu, Jan 20, 2022 at 6:49 PM Richard W.M. Jones wrote: > On Wed, Jan 19, 2022 at 01:30:54PM +0100, Dmitry Belyavskiy wrote: > > On Wed, Jan 19, 2022 at 1:24 PM Sahana Prasad wrote: > > > > Hello everyone, > > > > Could anyone kindly help wi

Re: F37 Change: Curl-minimal as default (System-Wide Change proposal)

2022-02-23 Thread Dmitry Belyavskiy
al, even in an update of a stable Fedora release. So I do > not think we need to enable it proactively. > > Being from Russia and having several years of interacting with Universal Acceptance, I'd say IDN is a must nowadays. -- Dmitry Belyavskiy __

OpenSSH 8.7p1 in rawhide

2021-09-29 Thread Dmitry Belyavskiy
security release) are expected to use SFTP protocol by default. This behavior (SFTP as a default transfer protocol for scp utility) is backported to rawhide. The same approach is planned for RHEL 9 GA, Please let me know if you have any questions/problems. Many thanks in advance! -- Dmitry

Re: OpenSSH 8.7p1 in rawhide

2021-10-04 Thread Dmitry Belyavskiy
Dear Richard, On Mon, Oct 4, 2021 at 10:23 AM Richard W.M. Jones wrote: > On Wed, Sep 29, 2021 at 04:48:43PM +0200, Dmitry Belyavskiy wrote: > > Dear colleagues, > > > > I recently added OpenSSH 8.7p1 to rawhide. > > This version includes implementation of th

Re: Landing a larger-than-release change (distrusting SHA-1 signatures)

2022-03-09 Thread Dmitry Belyavskiy
s://fedoraproject.org/wiki/Mailing_list_guidelines > List Archives: > https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org > Do not reply to spam on the list, report it: > https://pagure.io/fedora-infrastructure > -- Dmitry Belyavskiy

Re: openssl maintainerships?

2022-03-16 Thread Dmitry Belyavskiy
eam 9 is once again > higher than in Fedora. > > -- > Miro Hrončok > -- > Phone: +420777974800 > IRC: mhroncok > > -- Dmitry Belyavskiy ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to deve

Re: openssl maintainerships?

2022-03-16 Thread Dmitry Belyavskiy
r Robinson wrote: > On Wed, Mar 16, 2022 at 10:04 AM Dmitry Belyavskiy > wrote: > > > > Dear Peter, dear Miro, > > > > The immediate reason for the lack of update of OpenSSL in Fedora was a > problem with kTLS in avmv7. > > We tried to get some feedback but

Re: Fedora rawhide (to be f41) and openssl engines

2024-09-18 Thread Dmitry Belyavskiy
lt in koji. I'm ok with porting this to F41 -- Dmitry Belyavskiy -- ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.o

Re: Fedora rawhide (to be f41) and openssl engines

2024-10-02 Thread Dmitry Belyavskiy
It was recently merged to f41 On Mon, Sep 23, 2024 at 11:37 AM Iñaki Ucar wrote: > > > > On Wed, 18 Sept 2024 at 15:36, Dmitry Belyavskiy wrote: >> >> Dear colleagues, >> >> On Tue, Sep 17, 2024 at 10:05 PM Jonathan Wakely wrote: >> >> >

Re: pkcs11-provider update breaks eduroam

2024-11-20 Thread Dmitry Belyavskiy
upplicant does not need pkcs11-provider *at the moment*, because > it uses engine API for pkcs11 (and that is going to be a problem in > the future for EAP-TLS with pkcs11, if engine disappears from > openssl). However, it loads the legacy provider at startup, because

Re: pkcs11-provider update breaks eduroam

2024-11-21 Thread Dmitry Belyavskiy
Dear Davide, On Thu, Nov 21, 2024 at 1:07 PM Davide Caratti wrote: > hello, > > On Wed, Nov 20, 2024 at 12:48 PM Dmitry Belyavskiy > wrote: > > > > [...] > >> > The idea here was to auto-enable pkcs11-provider when it is > installed, which still makes

Orphaning openssl-gost-engine

2025-01-23 Thread Dmitry Belyavskiy
Dear colleagues, I orphan openssl-gost-engine for personal reasons -- Dmitry Belyavskiy -- ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https

Re: Orphaning openssl-gost-engine

2025-01-25 Thread Dmitry Belyavskiy
Hi Carlos, Thank you for your email! I'd like to have a talk about it if possible On Sat, Jan 25, 2025 at 3:30 PM Carlos Rodriguez-Fernandez < carlosrodrifernan...@gmail.com> wrote: > I'll take it. Thank you Dmitry. > > > On 1/23/25 10:38 AM, Dmitry Belyavskiy wrote

PQ algorithms in Fedora 41 - improvements

2025-01-17 Thread Dmitry Belyavskiy
L-KEM. Many thanks! -- Dmitry Belyavskiy -- ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

Re: F43 change Proposal: Disabling support of building OpenSSL engines (system-wide)

2025-02-25 Thread Dmitry Belyavskiy
and corresponding API is deprecated since OpenSSL 3.0. > > The engine functionality we are aware of (PKCS#11, TPM) is covered by > > providers. > > Are providers FIPS compatible? > Some of them - yes. We have a dedicated FIPS provider, and also AFAIK PKCS#11 provider is FIPS-comp

Re: F43 change Proposal: Disabling support of building OpenSSL engines (system-wide)

2025-02-25 Thread Dmitry Belyavskiy
ing_ applications wit engine support. -- Dmitry Belyavskiy -- ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/cod

Re: Proposal: Allow all packagers to push empty commits to any package

2025-02-20 Thread Dmitry Belyavskiy
Hello, On Thu, Feb 20, 2025 at 2:27 PM Miro Hrončok wrote: > On 20. 02. 25 14:08, Dmitry Belyavskiy wrote: > > > > > > On Thu, Feb 20, 2025 at 1:17 PM Miro Hrončok > <mailto:mhron...@redhat.com>> wrote: > > > > > > What if we allowed

Re: Proposal: Allow all packagers to push empty commits to any package

2025-02-20 Thread Dmitry Belyavskiy
for rawhide itself but if you use rawhide as a starting point to cherry-pick downwards, it's more problematic. -- Dmitry Belyavskiy -- ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lis

Re: F43 change Proposal: Disabling support of building OpenSSL engines (system-wide)

2025-02-26 Thread Dmitry Belyavskiy
ct that ENGINE will eventually be removed relatively soon (in 4.0), I'm not so sure about other deprecated API. -- Dmitry Belyavskiy -- ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.f

Re: F43 change Proposal: Disabling support of building OpenSSL engines (system-wide)

2025-02-26 Thread Dmitry Belyavskiy
oject/code-of-conduct/ > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines > List Archives: > https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org > Do not reply to spam, report it: > https://pagure.io/fedora-infrastructure/new_issue >

Re: F43 change Proposal: Disabling support of building OpenSSL engines (system-wide)

2025-02-25 Thread Dmitry Belyavskiy
9.19+? Let me repeat. OpenSSL 4.0 without engine support will be here in, I'd say, F44, and compat package will not help you to _build_ the packages depending on engines. -- Dmitry Belyavskiy -- ___ devel mailing list -- devel@lists.fedoraproject.org

Re: Fedora gating tests to openssh

2025-03-07 Thread Dmitry Belyavskiy
On Fri, Mar 7, 2025 at 12:04 PM František Šumšal wrote: > Hey, > > On 3/6/25 19:02, Dmitry Belyavskiy wrote: > > Dear colleagues, > > > > I see that Fedora gating tests for OpenSSH fail because of, among > others, ownership/permission tests failure [1]. > > &g

Fedora gating tests to openssh

2025-03-06 Thread Dmitry Belyavskiy
he PR was not processed). Could anybody please remind me the proper procedure? Thank you! [1] https://artifacts.dev.testing-farm.io/7a6fef07-41f3-40a2-8ee8-c327934eddcd/ [2] https://fedoraproject.org/wiki/Changes/SSHKeySignSuidBit -- Dmitry Belya

Re: F43 Change Proposal: Package builds are expected to be reproducible (system-wide)

2025-03-20 Thread Dmitry Belyavskiy
solve the issue completely. > > Does this issue affect only Haskell packages? E.g. openssl is also built with -j8 and switching back to single thread will significantly increase compilation time -- Dmitry Belyavskiy -- ___ devel mailing list -- devel@lists

Re: Problems pushing OpenSSH to f42

2025-03-20 Thread Dmitry Belyavskiy
Thank you very much, looks like now it is pushed to stable On Wed, Mar 19, 2025 at 6:35 PM Kevin Fenzi wrote: > On Wed, Mar 19, 2025 at 10:26:33AM +0100, Dmitry Belyavskiy wrote: > > Dear Petr, > > Thank you for the investigation! > > I think it happened because the buil

Problems pushing OpenSSH to f42

2025-03-19 Thread Dmitry Belyavskiy
esting', 'f41-flatpak-updates-testing', 'f43-container-updates-testing', 'epel10.0-testing', 'f43-flatpak-updates-testing', 'f43-updates-testing']." Could anybody please resolve this situation? [1] https://bodhi.fedoraproject.org/updates/FE